Tools

Typography

Share This

While the prospect of damaging infrastructure through computer worms is now a real threat, IBM accumulates a small arsenal of technologies to fight the inevitable battle to protect our smarter, but more fragile, planet.

It's quite common for geeks to be science fiction fans, and I don't know if I'm a geek, but I do like a good sci-fi movie. Thus, I can't wait until tonight to go see Battle: Los Angeles, which opens today and tells the story of a Marine platoon's efforts to repel an alien invasion of the city of angels. Science fiction battles, like actual war, are glorified in the abstract, but you wouldn't want to be there if it were happening in real life. Thus it is with grave concern that I read about the cyber attacks on Iranian nuclear facilities using what is believed to be the Stuxnet worm.

Speculation is that Israel, with the support of the United States, tested the effect of the Stuxnet worm at a secret facility in Israel's Negev desert. Agents reportedly were spinning nuclear centrifuges similar to those located in Iran at Dimona, an Israeli nuclear arms complex, according to the New York Times. Apparently Iran's nuclear enrichment program, which uses the centrifuges, as well as a nuclear power plant under construction at Bushehr, were damaged by the worm. There is debate over the extent of the damage, and the Iranians deny that the worm caused any significant setbacks, though they concede it was found on technicians' laptops. Others, however, say the nuclear reactor was at risk of an actual meltdown had it been started up following the cyber attack.

While some are saying that disabling Iran's nuclear facilities may offset or delay military action against the Mideast country with persistent nuclear ambitions, the countermeasure may go down in history as one of the first examples of cyberwarfare or cyberterrorism. To understand what is occurring, you have to realize that a lot of machines and physical equipment in today's complex societies are run by computers. The equipment is controlled by what are known as SCADA systems, which stands for "supervisory control and data acquisition." These systems monitor and control physical processes, including things like traffic lights as well as some biggies like electricity transmission, oil and gas pipelines, and water distribution. Oh—and let's add nuclear power plant operation to that list.

Of course, all the important SCADA systems in North America and Europe are hardened against any sort of attack, from computer worm and other threats, right? Well, we wish that were the case. The truth is, SCADA-based systems are quite vulnerable to cyberwarefare attacks, and some people are quietly waiting for the other shoe to drop. What do they say about people living in glass houses?

Stuxnet was first reported on publicly in June 2010, but its presence probably goes back to the prior year. It appears to target Siemens' WinCC/PCS7 systems running on MS Windows. It uses four zero-day attacks to install a rootkit. This logs into the SCADA database and "steals design and control files," according to one report. Apparently, the program can change the control system and then even hide its changes.

Such a worm has the ability to cause untold damage to today's industrial, infrastructure, or facility-based processes. Imagine if it got into the systems controlling the electricity grid and caused unpredictable and hard-to-trace power outages. Most water today has to be treated before people can drink it. If the water treatment plants all were to shut down at the same time, how much potable water is on hand, and how long would it last? It's difficult to imagine what might happen if the radar and communications suddenly went haywire at a major metropolitan airport. Such occurrences could result if the systems became infected by Stuxnet or a similar worm.

Despite the potential severity of such an attack, there is a general lack of concern about security in SCADA-based systems. Some believe they are protected by their relative obscurity and proprietary interfaces; others mistakenly believe they are safe because the systems may not be connected to the Internet. Both assumptions are almost dreamlike in their naiveté. The truth is, SCADA systems are vulnerable to unauthorized access to the control software, either through a virus or human intervention, as well as access to the networks connecting SCADA devices. While protection of the network with cryptographic devices is assumed to block any access to the SCADA control software, the network jacks and switches provide a means for bypassing security. And in the case of public agencies charged with protecting many of these critical systems, there isn't a lot of extra money floating around today to spend on beefed-up security.

The security industry and independent organizations are well aware of the national threat and are quietly making inroads to at least to create some standards against which companies and agencies may be evaluated, but progress is slow. The hope is that they will complete their work before "something happens."

IBM also is well aware of the increasing threat to SCADA, as well as other computer systems running operations of various large public and privately held corporations. The company has nine worldwide research labs innovating security technology and nine security operations centers around the world to support clients. It has acquired no fewer than four security firms in about a year—Watchfire, Ounce Labs, Telelogic, and BigFix, many of which focus on smart devices, themselves raising untold concerns among IT security professionals.

IBM Security Solutions now has an extensive portfolio of hardware, software solutions, and professional and managed services that address the full range of IT security risks. It recently announced a collaboration with Trend Micro in which it integrates the company's ant-malware solution into IBM's new Tivoli Endpoint Management platform. The company also just introduced a new network security appliance, the IBM Security Network Intrusion Prevention System (IPS) GX7800, which protects Web applications and data in the cloud, all while operating at an estimated 20 GBps.

"The endpoint of 2011 is no longer just a PC or laptop," says Steve Robinson, general manager of IBM Security Solutions. It's "the entire range of interconnected and instrumented devices and sensors that comprise the smarter planet," he says. "From electrical grids to mobile devices, transportation systems, and buildings, the proliferation of these intelligent systems is creating new security loopholes that businesses need to address," says Robinson. "On today's smarter planet, everything is an endpoint and must be managed and secured like any other critical business asset."

By 2015, it is expected there will be 300 million smart electrical meters deployed worldwide. While each has the potential to save money and improve efficiency, they can also present an opportunity for a security breach, since they can sense and interact with other devices.

Protecting all these computer systems that constitute the smart planet isn't going to come cheap. As the risks associated with securing these systems and endpoints becomes increasingly complex, the cost of managing and securing them will rise. IDC estimates that the endpoint security market will increase at a compound annual growth rate of 8.3 percent to reach nearly $10 billion by 2014.

The race against time appears to be on, and one wonders what form the security breaches will take before a major SCADA system—outside of Iran—is infected or damaged. Will all the companies and public agencies that need to protect their systems be able to do so, and have the money to act, before "something happens"?

I suppose if you're in the security industry, your work is cut out for you. You might even declare: "Let the cyberwars begin!" Me, I'll be satisfied with a new interpretation of a good old alien invasion—the kind that's not real.

Chris Smith was the Senior News Editor at MC Press Online from 2007 to 2012 and was responsible for the news content on the company's Web site. Chris has been writing about the IBM midrange industry since 1992 when he signed on with Duke Communications as West Coast Editor of News 3X/400. With a bachelor's from the University of California at Berkeley, where he majored in English and minored in Journalism, and a master's in Journalism from the University of Colorado, Boulder, Chris later studied computer programming and AS/400 operations at Long Beach City College. An award-winning writer with two Maggie Awards, four business books, and a collection of poetry to his credit, Chris began his newspaper career as a reporter in northern California, later worked as night city editor for the Rocky Mountain News in Denver, and went on to edit a national cable television trade magazine. He was Communications Manager for McDonnell Douglas Corp. in Long Beach, Calif., before it merged with Boeing, and oversaw implementation of the company's first IBM desktop publishing system there. An editor for MC Press Online since 2007, Chris has authored some 300 articles on a broad range of topics surrounding the IBM midrange platform that have appeared in the company's eight industry-leading newsletters. He can be reached at chriswriting@cs.com.

LATEST COMMENTS

MC Press Online

RESOURCE CENTER

WHITE PAPERS

WEBCAST

TRIAL SOFTWARE

Mobile Computing and the IBM i

Mobile computing is rapidly maturing into a solid platform for delivering enterprise applications. Many IBM i shops today are realizing that integrating their IBM i with mobile applications is the fast path to improved business workflows, better customer relations, and more responsive business reporting.

This ASNA whitepaper takes a look at mobile computing for the IBM i. It discusses the different ways mobile applications may be used within the enterprise and how ASNA products solve the challenges mobile presents. It also presents the case that you already have the mobile programming team your projects need: that team is your existing RPG development team!

Automate IBM i Operations using Wireless Devices

Download the technical whitepaper on MANAGING YOUR IBM i WIRELESSLY and (optionally) register to download an absolutely FREE software trail. This whitepaper provides an in-depth review of the native IBM i technology and ACO MONITOR's advanced two-way messaging features to remotely manage your IBM i while in or away from the office. Notify on-duty personnel of system events and remotely respond to complex problems (via your Smartphone) before they become critical-24/7. Problem solved!

White Paper: Node.js for Enterprise IBM i Modernization

If your business is thinking about modernizing your legacy IBM i (also known as AS/400 or iSeries) applications, you will want to read this white paper first!

Download this paper and learn how Node.js can ensure that you: - Modernize on-time and budget - no more lengthy, costly, disruptive app rewrites! - Retain your IBM i systems of record - Find and hire new development talent - Integrate new Node.js applications with your existing RPG, Java, .Net, and PHP apps - Extend your IBM i capabilties to include Watson API, Cloud, and Internet of Things

2020 IBM i Marketplace Survey Results

This year marks the sixth edition of the popular IBM i Marketplace Survey Results. Each year, HelpSystems sets out to gather data about how businesses use the IBM i platform and the IT initiatives it supports. Year over year, the survey has begun to reveal long-term trends that give insight into the future of this trusted technology.

More than 500 IBM i users from around the globe participated in this year’s survey, and we’re so happy to share the results with you. We hope you’ll find the information interesting and useful as you evaluate your own IT projects.

AIX Security Basics eCourse

With so many organizations depending on AIX day to day, ensuring proper security and configuration is critical to ensure the safety of your environment. Don’t let common threats put your critical AIX servers at risk. Avoid simple mistakes and start to build a long-term plan with this AIX Security eCourse. Enroll today to get easy to follow instructions on topics like:

Removing extraneous files

Patching systems efficiently

Setting and validating permissions

Managing service considerations

Getting overall visibility into your networks

Developer Kit: Making a Business Case for Modernization and Beyond

Having trouble getting management approval for modernization projects? The problem may be you're not speaking enough "business" to them.

This Developer Kit provides you study-backed data and a ready-to-use business case template to help get your very next development project approved!

What to Do When Your AS/400 Talent Retires

IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators is small.

This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn:

IBM i Resources Retiring?

Let’s face it: IBM i experts and RPG programmers are retiring from the workforce. Are you prepared to handle their departure? Our panel of IBM i experts—Chuck Losinski, Robin Tatam, Richard Schoen, and Tom Huntington—will outline strategies that allow your company to cope with IBM i skills depletion by adopting these strategies that allow you to get the job done without deep expertise on the OS: - Automate IBM i processes - Use managed services to help fill the gaps - Secure the system against data loss and virusesThe strategies you discover in this webinar will help you ensure that your system of record—your IBM i—continues to deliver a powerful business advantage, even as staff retires.

Backup and Recovery Considerations for Security Data and Encrypted Backups

Security expert Carol Woodbury is joined by Debbie Saugen. Debbie is an expert on IBM i backup and recovery, disaster recovery, and high availability, helping IBM i shops build and implement effective business continuity plans. In today’s business climate, business continuity is more important than ever. But 83 percent of organizations are not totally confident in their backup strategy. During this webinar, Carol and Debbie discuss the importance of a good backup plan, how to ensure you’re backing up your security information, and your options for encrypted back-ups.

Profound.js: The Agile Approach to Legacy Modernization

In this presentation, Alex Roytman and Liam Allan will unveil a completely new and unique way to modernize your legacy applications. Learn how Agile Modernization:- Uses the power of Node.js in place of costly system re-writes and migrations - Enables you to modernize legacy systems in an iterative, low-risk manner - Makes it easier to hire developers for your modernization efforts - Integrates with Profound UI (GUI modernization) for a seamless, end-to-end legacy modernization solution

Data Breaches: Is IBM i Really at Risk?

IBM i is known for its security, but this OS could be more vulnerable than you think. Although Power Servers often live inside the safety of the perimeter firewall, the risk of suffering a data leak or data corruption remains high. Watch noted IBM i security expert Robin Tatam as he discusses common ways that this supposedly “secure” operating system may actually be vulnerable and who the culprits might be.

Easy Mobile Development

Watch this on-demand webinar and learn how to rapidly and easily deploy mobile apps to your organization – even when working with legacy RPG code! IBM Champion Scott Klement will demonstrate how to: - Develop RPG applications without mobile development experience - Deploy secure applications for any mobile device - Build one application for all platforms, including Apple and Android - Extend the life and reach of your IBM i (aka iSeries, AS400) platform You’ll see examples from customers who have used our products and services to deliver the mobile applications of their dreams, faster and easier than they ever thought possible!

Profound UI: Unlock True Modernization from your IBM i Enterprise

Modern, web-based applications can make your Enterprise more efficient, connected and engaged. This session will demonstrate how the Profound UI framework is the best and most native way to convert your existing RPG applications and develop new modern applications for your business. Additionally, you will learn how you can address modernization across your Enterprise, including databases and legacy source code, with Profound Logic.

Node Webinar Series Pt. 1: The World of Node.js on IBM i

Have you been wondering about Node.js? Our free Node.js Webinar Series takes you from total beginner to creating a fully-functional IBM i Node.js business application.

Part 1 will teach you what Node.js is, why it's a great option for IBM i shops, and how to take advantage of the ecosystem surrounding Node.

In addition to background information, our Director of Product Development Scott Klement will demonstrate applications that take advantage of the Node Package Manager (npm).

5 New and Unique Ways to Use the IBM i Audit Journal

You must be asking yourself: am I doing everything I can to protect my organization’s data? Tune in as our panel of IBM i high availability experts discuss:

- Why companies don’t test role swaps when they know they should - Whether high availability in the cloud makes sense for IBM i users - Why some organizations don’t have high availability yet - How to get high availability up and running at your organization - High availability considerations for today’s security concerns

Profound.js 2.0: Extend the Power of Node to your IBM i Applications

In this Webinar, we'll demonstrate how Profound.js 2.0 enables you to easily adopt Node.js in your business, and to take advantage of the many benefits of Node, including access to a much larger pool of developers for IBM i and access to countless reusable open source code packages on npm (Node Package Manager). You will see how Profound.js 2.0 allows you to:

Make Modern Apps You'll Love with Profound UI & Profound.js

Whether you have green screens or a drab GUI, your outdated apps can benefit from modern source code, modern GUIs, and modern tools. Profound Logic's Alex Roytman and Liam Allan are here to show you how Free-format RPG and Node.js make it possible to deliver applications your whole business will love:

Transform legacy RPG code to modern free-format RPG and Node.js

Deliver truly modern application interfaces with Profound UI

Extend your RPG applications to include Web Services and NPM packages with Node.js

Accelerating Programmer Productivity with Sequel

Most business intelligence tools are just that: tools, a means to an end but not an accelerator. Yours could even be slowing you down. But what if your BI tool didn't just give you a platform for query-writing but also improved programmer productivity? Watch the recorded webinar to see how Sequel:

Makes creating complex results simple

Eliminates barriers to data sources

Increases flexibility with data usage and distribution

Accelerated productivity makes everyone happy, from programmer to business user.

Business Intelligence is Changing: Make Your Game Plan

It’s time to develop a strategy that will help you meet your informational challenges head-on. Watch the webinar to learn how to set your IT department up for business intelligence success. You’ll learn how the right data access tool will help you:

Access IBM i data faster

Deliver useful information to executives and business users

Empower users with secure data access

Ready to make your game plan and finally keep up with your data access requests?

Controlling Insider Threats on IBM i

Let’s face facts: servers don’t hack other servers. Despite the avalanche of regulations, news headlines remain chock full of stories about data breaches, all initiated by insiders or intruders masquerading as insiders. User profiles are often duplicated or restored and are rarely reviewed for the appropriateness of their current configuration. This increases the risk of the profile being able to access data without the intended authority or having privileges that should be reserved for administrators. Watch security expert Robin Tatam as he discusses a new approach for onboarding new users on IBM i and best-practices techniques for managing and monitoring activities after they sign on.

- Accessing real-time data, so you can make real-time decisions - Providing run-time prompts, so users can help themselves - Delivering instant results in Microsoft Excel and PDF, without the wait - Automating the query process with on-demand data, dashboards, and scheduled jobs

How to Manage Documents the Easy Way

What happens when your company depends on an outdated document management strategy? Everything is harder.You don’t need to stick with status quo anymore. Watch the webinar to learn how to put effective document management into practice and:

Capture documents faster, instead of wasting everyone’s time

Manage documents easily, so you can always find them

Distribute documents automatically, and move on to the next task

Lessons Learned from the AS/400 Breach

Get actionable info to avoid becoming the next cyberattack victim. In “Data breach digest—Scenarios from the field,” Verizon documented an AS/400 security breach. Whether you call it AS/400, iSeries, or IBM i, you now have proof that the system has been breached. Watch IBM i security expert Robin Tatam give an insightful discussion of the issues surrounding this specific scenario. Robin will also draw on his extensive cybersecurity experience to discuss policies, processes, and configuration details that you can implement to help reduce the risk of your system being the next victim of an attack.

Overwhelmed by Operating Systems?

In this 30-minute recorded webinar, our experts demonstrate how you can:

Manage multiple platforms from a central location

View monitoring results in a single pane of glass on your desktop or mobile device

Real-Time Disk Monitoring with Robot Monitor

You need to know when IBM i disk space starts to disappear and where it has gone before system performance and productivity start to suffer. Our experts will show you how Robot Monitor can help you pinpoint exactly when your auxiliary storage starts to disappear and why, so you can start taking a proactive approach to disk monitoring and analysis. You’ll also get insight into:

The main sources of disk consumption

How to monitor temporary storage and QTEMP objects in real time

How to monitor objects and libraries in real time and near-real time

How to track long-term disk trends

Stop Re-keying Data Between IBM I and Other Applications

Many business still depend on RPG for their daily business processes and report generation.Wouldn’t it be nice if you could stop re-keying data between IBM i and other applications? Or if you could stop replicating data and start processing orders faster? Or what if you could automatically extract data from existing reports instead of re-keying? It’s all possible. Watch this webinar to learn about:

The data dilemma

3 ways to stop re-keying data

Data automation in practice

Plus, see how HelpSystems data automation software will help you stop re-keying data.

The Top Five RPG Open Access Myths....BUSTED!

When it comes to IBM Rational Open Access: RPG Edition, there are still many misconceptions - especially where application modernization is concerned!

In this Webinar, we'll address some of the biggest myths about RPG Open Access, including:

The RPG language is outdated and impractical for modernizing applications

Modernizing with RPG OA is the equivalent to "screen scraping"

Time to Remove the Paper from Your Desk and Become More Efficient

Too much paper is wasted. Attempts to locate documents in endless filing cabinets.And distributing documents is expensive and takes up far too much time. These are just three common reasons why it might be time for your company to implement a paperless document management system. Watch the webinar to learn more and discover how easy it can be to:

Capture

Manage

And distribute documents digitally

IBM i: It’s Not Just AS/400

IBM’s Steve Will talks AS/400, POWER9, cognitive systems, and everything in between

Are there still companies that use AS400? Of course!

IBM i was built on the same foundation.Watch this recorded webinar with IBM i Chief Architect Steve Will and IBM Power Champion Tom Huntington to gain a unique perspective on the direction of this platform, including:

This is a unique, online opportunity to hear how you can get more out of RDi.

Node.js on IBM i Webinar Series Pt. 2: Setting Up Your Development Tools

Have you been wondering about Node.js? Our free Node.js Webinar Series takes you from total beginner to creating a fully-functional IBM i Node.js business application. In Part 2, Brian May teaches you the different tooling options available for writing code, debugging, and using Git for version control. Attend this webinar to learn:

Understanding what the integrated file system is and how to work with it must be a critical part of your systems management plans for IBM i.

Expert Tips for IBM i Security: Beyond the Basics

In this session, IBM i security expert Robin Tatam provides a quick recap of IBM i security basics and guides you through some advanced cybersecurity techniques that can help you take data protection to the next level. Robin will cover:

Reducing the risk posed by special authorities

Establishing object-level security

Overseeing user actions and data access

Don't miss this chance to take your knowledge of IBM i security beyond the basics.

5 IBM i Security Quick Wins

In today’s threat landscape, upper management is laser-focused on cybersecurity. You need to make progress in securing your systems—and make it fast. There’s no shortage of actions you could take, but what tactics will actually deliver the results you need? And how can you find a security strategy that fits your budget and time constraints? Join top IBM i security expert Robin Tatam as he outlines the five fastest and most impactful changes you can make to strengthen IBM i security this year. Your system didn’t become unsecure overnight and you won’t be able to turn it around overnight either. But quick wins are possible with IBM i security, and Robin Tatam will show you how to achieve them.

How to Meet the Newest Encryption Requirements on IBM i

A growing number of compliance mandates require sensitive data to be encrypted. But what kind of encryption solution will satisfy an auditor and how can you implement encryption on IBM i? Watch this on-demand webinar to find out how to meet today’s most common encryption requirements on IBM i. You’ll also learn:

Why disk encryption isn’t enough

What sets strong encryption apart from other solutions

Important considerations before implementing encryption

Security Bulletin: Malware Infection Discovered on IBM i Server!

Malicious programs can bring entire businesses to their knees—and IBM i shops are not immune. It’s critical to grasp the true impact malware can have on IBM i and the network that connects to it. Attend this webinar to gain a thorough understanding of the relationships between:

Viruses, native objects, and the integrated file system (IFS)

Power Systems and Windows-based viruses and malware

PC-based anti-virus scanning versus native IBM i scanning

There are a number of ways you can minimize your exposure to viruses. IBM i security expert Sandi Moore explains the facts, including how to ensure you're fully protected and compliant with regulations such as PCI.

Fight Cyber Threats with IBM i Encryption

Cyber attacks often target mission-critical servers, and those attack strategies are constantly changing. To stay on top of these threats, your cybersecurity strategies must evolve, too. In this session, IBM i security expert Robin Tatam provides a quick recap of IBM i security basics and guides you through some advanced cybersecurity techniques that can help you take data protection to the next level. Robin will cover:

Reducing the risk posed by special authorities

Establishing object-level security

Overseeing user actions and data access

10 Practical IBM i Security Tips for Surviving Covid-19 and Working From Home

Now that many organizations have moved to a work from home model, security concerns have risen.

During this session Carol Woodbury will discuss the issues that the world is currently seeing such as increased malware attacks and then provide practical actions you can take to both monitor and protect your IBM i during this challenging time.

How to Transfer IBM i Data to Microsoft Excel

3 easy ways to get IBM i data into Excel every time There’s an easy, more reliable way to import your IBM i data to Excel? It’s called Sequel. During this webinar, our data access experts demonstrate how you can simplify the process of getting data from multiple sources—including Db2 for i—into Excel. Watch to learn how to:

Download your IBM i data to Excel in a single step

Deliver data to business users in Excel via email or a scheduled job

Access IBM i data directly using the Excel add-in in Sequel

Make 2020 the year you finally see your data clearly, quickly, and securely. Start by giving business users the ability to access crucial business data from IBM i the way they want it—in Microsoft Excel.

HA Alternatives: MIMIX Is Not Your Only Option on IBM i

In this recorded webinar, our experts introduce you to the new HA transition technology available with our Robot HA software. You’ll learn how to:

Transition your rules from MIMIX (if you’re happy with them)

Simplify your day-to-day activities around high availability

Gain back time in your work week

Make your CEO happy about reducing IT costs

Don’t stick with a legacy high availability solution that makes you uncomfortable when transitioning to something better can be simple, safe, and cost-effective.

Manage IBM i Messages by Exception with Robot

Managing messages on your IBM i can be more than a full-time job if you have to do it manually. How can you be sure you won’t miss important system events? Automate your message center with the Robot Message Management Solution. Key features include: - Automated message management - Tailored notifications and automatic escalation - System-wide control of your IBM i partitions - Two-way system notifications from your mobile device - Seamless product integration Try the Robot Message Management Solution FREE for 30 days.

ACO MONITOR Manages your IBM i 24/7 and Notifies You When Your IBM i Needs Assistance!

More than a paging system - ACO MONITOR is a complete systems management solution for your Power Systems running IBM i. ACO MONITOR manages your Power System 24/7, uses advanced technology (like two-way messaging) to notify on-duty support personnel, and responds to complex problems before they reach critical status.

ACO MONITOR is proven technology and is capable of processing thousands of mission-critical events daily. The software is pre-configured, easy to install, scalable, and greatly improves data center efficiency.